Amazon Caught a North Korean IT Worker Through Keystroke Timing
Amazon reportedly uncovered a North Korean IT worker inside the company because of a 110-millisecond delay in their keystrokes.
That detail is remarkable because the person could otherwise look like an ordinary remote employee. IP checks can be defeated with a U.S.-based laptop farm. A real person's identity can pass document and background checks. A frontman can appear on camera. Yet the physical distance between the operator and the machine still created a behavioral trace.
The finding was reported by Bloomberg, which described Amazon security personnel tracing connections associated with a contractor.
Why the delay mattered
A worker typing directly on a company computer should produce a different timing pattern from an operator controlling that computer across a long-distance remote connection. Network routing, remote-desktop software, and the distance between the operator and the endpoint introduce latency.
In this case, a consistent delay of roughly 110 milliseconds reportedly became the decisive clue. It was not a resume typo or a suspicious profile photo. It was physics.
Candidate fraud is a layered problem
This is why surface-level fraud checks are not enough on their own.
- An IP address can point to the laptop farm instead of the operator.
- The laptop can be physically located in the employee's claimed city.
- Documents can belong to a real person whose identity was stolen or rented.
- A frontman can complete live identity verification.
- The person who interviews can be different from the person doing the daily work.
Any one signal can be explained away. The stronger approach combines identity, application, document, device, network, contact, and behavioral evidence—and keeps watching for continuity after the hire.
What hiring and security teams should take from it
Recruiting teams are usually the first line of defense because they see the application, resume, contact details, and interview trail. Security teams see a different part of the story after access is provisioned.
Those two views should connect. A suspicious application should not disappear into a recruiting system after the start date, and an unusual employee-session pattern should be reviewable alongside the original hiring evidence.
Amazon's reported finding is a useful reminder: sophisticated fraud rings can imitate documents, devices, and people, but they still have to operate a real system from somewhere. Layered evidence makes those residual signals visible.